Privacy Policy

Last updated

Kinnect Ltd ("Kinnect", "we", "us" or "our") respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, share and protect personal data when you use the Kinnect mobile app, Kinnect Hub, our marketing website and related services.

Kinnect helps people discover, join and take part in communities, events, plans and related conversations. Kinnect Hub provides authorised community and customer operators with workspace tools for managing events and linked communities, viewing permitted operational information, administering workspace access and managing agreements. To provide Kinnect, we collect information needed to create accounts, authenticate users, operate these services, support communities, show relevant events and plans, enable messaging and interactions, keep users safe, improve the service and comply with legal obligations.

In plain English

We collect the information needed to run Kinnect and help communities, events, plans and operator workspaces work properly.

Some of the information you provide is private to you or only visible to the people involved in the relevant feature. For example, community managers and Hub operators do not receive access to your password, private account settings, precise live location, or your activity in unrelated communities.

If you join a community or interact with an event, the relevant community creator, organiser, administrator or manager may be able to see limited information needed to manage that community or event. This may include your profile information, membership status, event registration or response status, attendance or check-in information, and responses you choose to submit for that community or event. Where available, an authorised operator may access this information through the app or Kinnect Hub.

Kinnect Hub may combine permitted information from more than one community linked to the same customer workspace, for example in a cross-group event list or aggregate briefing. These views remain limited to linked communities and authorised roles. Payment, workspace access or a Hub administrator role does not by itself expand access to member-level personal data.

Community and event information may still be personal data. We only make it visible to community managers and Hub operators where it is needed for legitimate and authorised community or event management.

We use your live location only to calculate approximate distance from you to an event, plan or community. Only you see that distance context. We do not share your live or precise location with community managers, other users, event organisers or plan participants. Kinnect does not track your live location in the background.

We do not sell your personal data.

1. Who we are

Kinnect Ltd is the controller of personal data processed through Kinnect, except where another person or organisation independently decides how and why personal data is used.

You can contact us about this Privacy Policy or your personal data at:

2. What this policy covers

This Privacy Policy applies to:

  • the Kinnect mobile app;

  • Kinnect Hub, including its personal and customer workspace contexts where available;

  • the Kinnect marketing website;

  • communities, events, plans, messages, comments, replies, reactions and other product features;

  • workspace accounts, roles, linked communities, agreements and permitted cross-group operational views;

  • communications with us, including support and service messages.

Kinnect Hub is currently a conditional, gated beta made available only to authorised users and approved customer workspaces. Availability may be delayed, limited, suspended or withdrawn while privacy, security, access-control and operational checks are completed.

The Hub descriptions in this Privacy Policy cover the approved gated-beta scope. Future features, including automated billing, integrations, deeper analytics or broader exports, are not covered as active processing unless and until they are enabled and this policy and the supporting governance records are updated where necessary.

This Privacy Policy does not apply to websites, apps or services operated independently by third parties, even if they are linked from Kinnect.

3. Information we collect

We collect personal data in the following ways.

3.1 Information you provide to us

Account information

When you create or use a Kinnect mobile app account, we may collect information such as your name, email address, phone number, username, password or authentication information, age or age confirmation, and account preferences.
When you create or use a Kinnect Hub account, we may collect your name, email address, authentication-provider identifier, sign-in method, authentication and session information, and account preferences. We use WorkOS to provide authentication for Kinnect Hub. Depending on the sign-in options made available, WorkOS may support email verification or sign-in through providers such as Google or Microsoft.
Where you sign in through another identity provider, Kinnect does not receive the password you use with that provider.

Hub account and workspace information

If you use Kinnect Hub, we may collect and maintain information such as:

  • your Hub account identifier;

  • the customer workspaces you can access;

  • your workspace role, such as OWNER or ADMIN;

  • workspace invitations, membership changes and access status;

  • the communities linked to the workspace;

  • the connection between your Hub account and an eligible Kinnect app account;

  • the communities and app resources you are authorised to manage;

  • events and other workspace records you create, import, edit or administer;

  • your use of Hub workspace features.
    A Hub account, workspace role or payment status does not by itself authorise access to app member data. Access to information from a linked community also depends on the relevant workspace grant, account link and current community role.

Contracts and agreements

If you review, accept or administer an agreement through Kinnect Hub, we may collect:

  • your name and workspace role;

  • the name you type or other method used to record acceptance;

  • the customer organisation and workspace concerned;

  • the document and version presented;

  • acceptance, sending and countersignature status;

  • relevant dates and times;

  • related audit and legal evidence.
    We use this information to administer the customer relationship, establish what was agreed, meet legal and financial obligations and handle disputes.

Profile information

You may choose to provide profile information, such as a profile photo, bio, interests, preferences, community affiliations or other information you add to your Kinnect profile.

Community information

When you join, create, manage or interact with a community, we may collect information such as:

  • the communities you join, create, follow or manage;

  • your role in a community, such as member, organiser, administrator or manager;

  • your membership status;

  • your activity within that community;

  • comments, replies or reactions you post on community updates;

  • moderation actions taken by community admins.

Event information

When you view, register for, respond to, attend or interact with an event, we may collect information such as:

  • event views and interactions;

  • registration status;

  • response status;

  • waiting list status;

  • attendance or check-in status;

  • responses you submit in relation to an event;

  • relevant event-related communications or interactions.

Plan information

When you create, receive, respond to or interact with a plan, we may collect information such as:

  • plan details;

  • whether you have received, viewed or responded to a plan;

  • your response to a plan;

  • plan location information, where provided;

  • messages and interactions within plan threads.

Plans may allow users who have responded to a plan shared by a contact to message each other. These messages may be individual or group messages depending on the plan and feature used.

Messages, comments, replies and reactions

Kinnect includes social and community interaction features. We may collect messages, comments, replies, reactions and related metadata, such as when the interaction occurred and which community, update, plan or thread it relates to.

Members of a community may be able to comment on updates shared by admins. Other members may be able to reply to those comments. Members may also be able to react to admin updates. Admins may be able to delete replies and moderate comments on their update posts.

Support and communications

If you contact us, report a problem, respond to a survey or communicate with us, we may collect the information you provide and records of our communications.

3.2 Information collected automatically

Usage and device information

We may collect information about how you use Kinnect, including app activity, screens viewed, features used, dates and times of access, device type, operating system, app version, IP address and diagnostic information.

Product analytics

We use product analytics to understand how Kinnect is used, improve the app, identify issues and develop better features. Product analytics may include information about app interactions, feature usage, session activity and technical performance.

Crash analytics and diagnostics

We use crash analytics and diagnostic information to identify bugs, fix crashes, improve reliability and maintain the security and performance of Kinnect.

Notifications

If you enable notifications, we may process notification tokens and related information to send push notifications, such as community updates, plan updates, event reminders, messages, replies, reactions, service messages and security alerts.

You can manage push notifications through your device settings or in-app settings where available.

Security, technical and audit information

We may collect information used to protect Kinnect, control access, prevent abuse, troubleshoot issues and maintain service reliability. This may include log data, authentication and session events, device identifiers, IP address, browser or user-agent information, security events and technical records.
For Kinnect Hub, audit information may also include Hub and app account identifiers, workspace and linked-community identifiers, role or access changes, agreement actions, resource-linking actions, authorisation results, token-exchange purpose and identifiers, timestamps and action status.
Audit information is used for access control, security, support, contract administration, incident response and accountability. It is not authority to give a user access to data.

3.3 Location information

Kinnect may use location information to provide location-based features.

If you enable location permissions, we may use your live location to calculate approximate distance from you to an event, plan or community. This helps you understand how close or far away something is.

Only you see this distance context. We do not share your live or precise location with community managers, other users, event organisers, plan creators or plan participants.

Kinnect does not track your live location in the background.

If you set a plan to your current location, Kinnect may use your current location to create a location marker for that plan. This does not create live location tracking. Other users only see the plan location you choose to share, not your continuing live location.

Checking in at a community location is based on the relevant address or community location information. It does not involve sharing your current live location with other users.

You can disable location permissions through your device settings. Some location-based features, such as distance context, may not work properly if location access is disabled.

3.4 Website information

When you visit our marketing website, we may collect basic information such as device information, browser information, IP address, pages viewed, referral information and cookie or similar technology data.

Where required, we will ask for consent before using non-essential cookies or similar technologies on our website.

3.5 Information from community managers or other users

Community creators, organisers, administrators or managers may provide information about communities, events or members. For example, they may create events, manage guest lists, view registrations, review responses, check attendance, moderate comments or manage community updates.

Other users may provide information that relates to you, such as when they invite you to a plan, message you in a plan thread, reply to your comment, react to content, report content or participate in the same community, event or plan.

3.6 Information from third parties

We may receive information from third parties where necessary to provide Kinnect, such as hosting providers, authentication providers, analytics providers, crash analytics providers, notification providers, app stores or other service providers that support the operation of Kinnect.
For Kinnect Hub, we receive authentication and session information from WorkOS. Depending on how you choose to sign in, WorkOS may also interact with an identity provider such as Google or Microsoft.
We may also receive information if another user invites you to Kinnect, shares a plan with you, adds you to a customer workspace or interacts with you through the service.
Kinnect does not currently process payments through the mobile app. Automated Hub billing is not part of the current gated-beta scope unless separately enabled. Contract, invoice and payment administration may take place through approved business processes or payment providers outside the mobile app.

4. How we use personal data

We use personal data for the purposes below.

4.1 To provide and operate Kinnect

We use personal data to:

  • create and manage mobile app and Hub accounts;

  • authenticate users and maintain authorised sessions;

  • administer customer workspaces, roles and access;

  • connect an authorised Hub account to an eligible app account;

  • link customer workspaces to approved communities;

  • provide app and Hub features;

  • enable users to discover, join and participate in communities;

  • enable authorised users to create, manage and attend events;

  • provide permitted cross-group event lists, briefings and risk distributions;

  • enable users to create, share and respond to plans;

  • provide plan threads, individual messages and group messages;

  • show relevant community, event and plan information;

  • process event registrations, responses and check-ins;

  • provide community and event management tools;

  • support admin updates, comments, replies, reactions and moderation;

  • administer customer agreements and acceptance records;

  • send notifications and service messages;

  • provide customer support;

  • maintain audit, security and access-control records;

  • maintain, troubleshoot and improve service reliability.

4.2 To support community, event and workspace management

Kinnect allows community creators, organisers, administrators and managers to manage their own communities and events. Where available, authorised operators may use Kinnect Hub to perform these activities across communities linked to their customer workspace.
If you join a community or interact with an event, the relevant manager or authorised Hub operator may be able to view information reasonably necessary to manage that community or event, such as:

  • your name and profile information;

  • your membership status;

  • your event registration or response status;

  • your waiting list status;

  • your attendance or check-in status;

  • responses you submit in relation to that community or event;

  • comments, replies or reactions you make within that community;

  • relevant engagement or activity within that community.
    Kinnect Hub may provide a combined event list or aggregated operational briefing across linked communities. A combined view does not authorise access to unrelated communities, private messages, private plan content or precise live location. Risk distributions and similar workspace-level insight should be aggregated and should not expose small groups where individual members are reasonably likely to be identified.
    Workspace OWNER and ADMIN roles provide different administrative capabilities. Owners may add or remove workspace administrators and, where enabled, administer agreements and legal settings. Administrators may view the workspace team but do not receive owner-only legal, agreement or future billing permissions. Both roles remain subject to the linked-community and live community-role checks that apply to the requested information or action.
    Community managers and Hub operators do not have access to your password, private account settings, precise live location, or activity in unrelated communities.
    Relevant information may be viewed through the app or, where enabled, Kinnect Hub. Kinnect does not currently provide unrestricted self-serve exports of member, event, registration, response, attendance or check-in data. Any aggregate or workflow-level export enabled through the Hub must remain limited to information the operator is already authorised to use.
    Community managers and Hub operators must use member information only for legitimate community and event management purposes and in accordance with the terms that apply to their use of Kinnect, this Privacy Policy and applicable law.

4.3 To provide plans and plan threads

Kinnect allows users to create, share and respond to plans.

If a contact shares a plan with you and you respond to it, you may be able to participate in a thread with other users who have responded to that plan. These threads may include individual or group messages, depending on the feature used.

Information you share in a plan thread may be visible to the other participants in that thread.

4.4 To provide comments, replies, reactions and moderation

Kinnect allows community admins to share updates. Members may be able to comment on those updates, reply to comments and react to updates.

Comments, replies and reactions may be visible to other members of the relevant community or to other users who can view the update.

Admins may be able to delete replies and moderate comments on their update posts. We may also moderate content or activity where needed to apply the terms and rules that govern the relevant service, protect users, investigate reports or keep Kinnect safe.

4.5 To communicate with you

We may use your contact details and notification preferences to send:

  • account and service messages;

  • security alerts;

  • event, community or plan notifications;

  • message, comment, reply or reaction notifications;

  • support responses;

  • important policy or service updates;

  • marketing communications, where permitted by law.

You can opt out of marketing communications at any time. You may still receive service, security and transactional messages where necessary.

4.6 To use location-based features

We may use location information to:

  • show distance context to events and plans;

  • help you understand the approximate distance to a location;

  • support location markers for plans;

  • support local discovery or location-based recommendations where available;

  • support check-in features based on community or event address information.

We do not share your precise location with other users.

4.7 To keep Kinnect safe and secure

We use personal data to:

  • protect accounts;

  • detect, prevent and investigate fraud, spam, misuse, security incidents and harmful behaviour;

  • apply the terms and policies that govern the relevant service;

  • moderate content or activity where appropriate;

  • record and review authentication, access, workspace, agreement and other security-relevant actions.

  • respond to reports, complaints or disputes;

  • protect the rights, safety and security of users, Kinnect and others.

4.8 To improve Kinnect

We may use personal data to:

  • understand how users use Kinnect;

  • improve app features and user experience;

  • test and develop new features;

  • measure app performance;

  • fix bugs and technical issues;

  • produce aggregated or anonymised insights.

Where we create aggregated or anonymised information, we use it in a way that does not identify you.

4.9 To comply with legal obligations and protect legal rights

We may use personal data where necessary to:

  • comply with legal or regulatory obligations;

  • respond to legal requests or proceedings;

  • establish, exercise or defend legal claims;

  • protect our rights, users and others.

5. Legal bases for processing

Where UK or EU data protection law applies, we rely on one or more of the following legal bases depending on the context:

  • performance of a contract;

  • legitimate interests;

  • consent;

  • compliance with a legal obligation;

  • protection of vital interests.

The legal basis depends on the purpose for which the personal data is being used.

6. What other users and community managers can see

Kinnect is a community app. Some information you provide may be visible to other users, community managers or plan participants depending on your settings, actions and the features you use.

Personal account and private activity data

Community managers, event organisers and other users do not receive access to:

  • your password or authentication information;

  • your private account settings;

  • your precise live location;

  • plans or plan threads they are not a participant in;

  • messages in plan threads they are not part of;

  • your activity in unrelated communities;

  • your private interactions outside the communities, events or plans they are involved in.

Community and event management data

If you join a community or interact with an event, the relevant community creator, organiser, administrator, manager or authorised Hub operator may be able to view limited information needed to manage that community or event.
This may include:

  • your name and profile information;

  • your membership status in that community;

  • your event registration or response status;

  • your waiting list status;

  • your attendance or check-in status;

  • responses you submit for that community or event;

  • comments, replies or reactions you make within that community;

  • relevant engagement or activity within that community.
    Community and event management data may still be personal data. The distinction is about who can see it and why, not whether it is personal data.
    Community managers and Hub operators can only see information relating to communities and events they are authorised to manage. They cannot see plans or plan threads they are not a participant in, precise live location, or activity in unrelated communities.
    Kinnect does not currently provide unrestricted self-serve exports of member, event, registration, response, attendance or check-in data. Any aggregate or workflow-level export enabled through the Hub does not expand the operator's access to the underlying member data.

Hub accounts, workspace roles and linked communities

Other authorised members of your customer workspace may be able to see your name, email address, workspace role and membership status where needed to administer the workspace.
A workspace owner may add or remove administrators. Administrators may view the workspace team but cannot use an administrator role alone to access data from a linked community. The relevant workspace grant, account link and current community role must also permit access.
A Hub workspace may contain links to more than one community. Authorised operators may use cross-group event lists and aggregated briefings for those linked communities. They cannot use the workspace to access other customer workspaces or unrelated communities.
Paying for Kinnect or receiving access to a customer workspace does not create a new entitlement to member-level personal data. Paid or future subscription features may provide additional workflow, history or suitably governed aggregate information, but may not bypass the underlying community and event permissions.

Plans and plan threads

Plans are shared social records visible to the intended participants and any feature surfaces that the plan is made available through.

If a contact shares a plan with you and you respond to it, you may be able to participate in a thread with other users who have responded to that plan. These threads may include individual or group messages depending on the feature used.

Information you share in a plan thread may be visible to the other participants in that thread. Community managers do not receive access to a plan or plan thread unless they are participants in it or it is part of a community feature they manage.

Location and distance context

Kinnect may use your live location to calculate approximate distance from you to an event, plan or community.

Only you see this distance context. We do not share your live or precise location with community managers, other users, event organisers, plan creators or plan participants.

If you set a plan to your current location, Kinnect may create a location marker for that plan. This is not live location tracking. Other users only see the plan location you choose to share, not your continuing live location.

Checking in at a community location is based on the relevant address or community location information. It does not involve sharing your current live location with other users.

7. Sharing personal data

We may share personal data in the following circumstances.

7.1 With community managers, Hub operators and other users

We share information with community managers, authorised Hub operators and other users only as needed to provide Kinnect's community, event, plan, messaging, comment, reply, reaction, moderation and workspace features.

Community managers and Hub operators can see limited community and event management data for communities and events they are authorised to manage. They cannot see plans or plan threads they are not entitled to access, precise live location, messages in plan threads they are not part of, or activity in unrelated communities.

Hub operators may receive combined event views and aggregated operational information across communities linked to their workspace. Workspace or payment status alone does not expand the underlying member-data permissions.

Other users can see information you choose to share with them or make available through product features, such as plan threads, comments, replies, reactions, community activity or event participation where the feature allows.

7.2 With service providers

We may share personal data with service providers who help us operate Kinnect, such as hosting, storage, analytics, crash reporting, communications, authentication, security and notification providers.

We use WorkOS to provide authentication and session services for Kinnect Hub. WorkOS may process identity, sign-in, session and security information on our behalf for that purpose.

These providers may process personal data on our behalf under contractual obligations and only for the services they provide to us.

7.3 With authorised Kinnect staff

Authorised Kinnect staff may access personal data where reasonably necessary to provision or link a workspace, provide support, administer agreements, investigate an access problem, protect the service, respond to an incident or meet legal obligations.

This may include relevant account, workspace, community, event, agreement, audit or technical information. Staff do not have unrestricted authority to browse customer or member information. Cross-workspace staff access must be separately authorised, limited to a genuine business need and subject to appropriate audit and review.

7.4 For legal, safety and business reasons

We may disclose personal data if we believe it is necessary to:

  • comply with law or legal process;

  • apply the terms and policies that govern the relevant service;

  • respond to claims, disputes or requests;

  • protect the safety, rights or property of Kinnect, our users or others;

  • record and review authentication, access, workspace, agreement and other security-relevant actions.

7.5 Business transfers

If Kinnect is involved in a merger, acquisition, reorganisation, financing, sale of assets or similar transaction, personal data may be transferred as part of that transaction, subject to applicable law.

8. International transfers

We may transfer personal data outside the United Kingdom or European Economic Area where necessary to provide Kinnect or use service providers.
Some providers used for hosting, analytics, authentication or other operational services may process personal data in countries including the United States, depending on the provider and service configuration.
Where required, we use appropriate safeguards to protect personal data when it is transferred internationally.

9. Data retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

The retention period depends on the type of data, the purpose for which it was collected, legal obligations, security needs and the risk of harm from keeping it longer than necessary.

When personal data is no longer needed, we will delete it or anonymise it where appropriate.

Hub accounts, workspace records and audit information

Hub account and workspace-membership information is kept while the account or access remains active and for as long afterwards as needed for support, security, legal claims and accountable administration.
If workspace access is removed, we may retain limited records showing the former role, access change and relevant actions. Agreement and acceptance records may be retained after Hub access ends where needed to establish what was agreed, meet legal or financial obligations or handle disputes.
Hub authentication, security and audit records are retained only for the operational, security, legal or accountability period that applies to the record. Authentication information held by WorkOS is also subject to our service arrangement with WorkOS.
The relationship between Hub account deletion, workspace removal, app-account unlinking and deletion of a separate Kinnect mobile app account depends on the accounts and services affected. You can contact us to request deletion or clarification.

Account deletion and shared activity

You may request account deletion through the available account settings or by contacting hugo@kinnect.io.

Account deletion is irreversible. Once your account is closed, you will lose normal access to it.

Deleting an account is intended to:

  • prevent further authentication and ordinary account use;

  • remove your direct profile and contact identity from the parts of Kinnect visible to users;

  • delete or anonymise private account data where no continuing lawful purpose exists; and

  • stop ordinary notification and discovery activity associated with the account.

Some shared social or operational records may remain where deleting them would remove information that other authorised users or communities still reasonably need. These may include:

  • messages already sent to other participants;

  • shared plans and plan threads;

  • community posts, comments, replies and other community history;

  • events created or managed through a community;

  • registration, attendance or participation history; and

  • limited records needed for safety, security, legal claims or proof that deletion was completed.

Where shared records are retained, we remove ordinary profile links and identify the former account as "Deleted user", "Former member" or another appropriate non-identifying label. This reduces direct identification but does not necessarily make a retained record anonymous, because its content or context may still relate to you. We continue to apply appropriate access and retention controls to those records.

Residual copies may remain temporarily in backups or with service providers while the applicable deletion, anonymisation, disconnection or expiry process is completed. These copies remain subject to our security and retention controls. Deleting your account does not require another person to delete an independent copy of content you previously shared with them.

You can contact us to request deletion or if retained content exposes a private address, sensitive information or another serious risk that requires individual review.

10. Your rights

Depending on where you live, you may have rights to:

  • access your personal data;

  • correct inaccurate personal data;

  • delete your personal data;

  • object to or restrict certain processing;

  • withdraw consent where processing is based on consent;

  • receive a copy of certain personal data in a portable format;

  • lodge a complaint with a data protection authority.

You can contact us using the details above to exercise your rights.

11. Children and age restrictions

Kinnect is intended for users aged 13 and over.

If we learn that we have collected personal data from a child in a way that does not comply with applicable law, we will take appropriate steps to delete or protect that information.

12. Security

We use technical and organisational measures designed to protect personal data, including access controls, role and relationship checks, short-lived credentials, security monitoring, logging, restricted staff access and other safeguards appropriate to the nature of the data and the risk involved.
For Kinnect Hub, a successful sign-in, customer workspace role or payment status does not by itself authorise access to linked-community data. Additional access and current community-role checks apply.
No method of transmission or storage is completely secure, but we work to protect personal data using measures appropriate to the risk.

13. Cookies and similar technologies

We use cookies or similar technologies on our website and Kinnect Hub where necessary to provide authentication, maintain secure sessions, remember preferences and operate the service.
Where required, we ask for consent before using non-essential cookies or similar technologies.
You can control cookies through your browser settings and any cookie preferences we provide. Disabling necessary cookies may prevent sign-in or other Hub features from working.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.
If we make material changes, we will take appropriate steps to notify you, such as by posting the updated policy in the app, Kinnect Hub or on our website, or by sending an account or service message where appropriate.

15. Contact us

If you have questions about this Privacy Policy or how we handle your personal data, please contact us at: